Uber has internal data stolen in yet another cyberattack


A recent supply chain attack has resulted in sensitive data belonging to Uber drivers being stolen once again.
The Register picked up on a breach notification sent to affected drivers by the law firm Genova Burns which said that in late January 2023 it “became aware” of suspicious activity in its internal information systems.
After bringing in outside forensic and data security specialists, the company determined that an “unauthorized third party” (no groups or individuals were named) accessed its systems between January 23 and 31, 2023. During that time, the threat actor stole data including Uber drivers’ names, Social Security Numbers, and in some cases, Tax Identification numbers.
Securing the environment
The way the notification was formulated suggests that this is not all of the data that was taken, but Genova Burns did not discuss it further.
What it did discuss are its moves going forward, including the usual 12 months of free identity (opens in new tab) monitoring services, this time through Kroll. It also said it “secured the environment” by changing all system passwords, and notifying the police.
“We will be taking additional steps to improve security and better help protect against similar incidents in the future,” Genova Burns added, without detailing which additional steps those are.
When asked by the publication to comment, Uber sent an email statement, saying the Genova Burns data was related to “certain drivers who had completed trips in New Jersey”. The company also reminded that the law firm found no evidence of the data being used in the wild, or evidence of such an attempt.
Genova Burns said it held the data due to its legal representation of Uber Technologies.
Uber has suffered its fair share of cybersecurity incidents, including the 2016 data theft fiasco, the 2022 Lapsus$ data theft, and the Teqtivity supply chain attack.
Via: The Register (opens in new tab)
A recent supply chain attack has resulted in sensitive data belonging to Uber drivers being stolen once again. The Register picked up on a breach notification sent to affected drivers by the law firm Genova Burns which said that in late January 2023 it “became aware” of suspicious activity in…
Recent Posts
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin will suffer a humane death
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
- DOGE can keep accessing government data for now, judge rules
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010